CVE-2022-37019

MEDIUM
Published Jun 10, 2024 Modified Jan 14, 2026 CWE-269

Description

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

Is your site exposed to CVE-2022-37019?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.8
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Weakness Type (CWE)

CWE-269 CWE-269

Affected Products

Vendor Product
hp elite_slice_firmware
hp elite_slice
hp elite_slice_for_meeting_rooms_firmware
hp elite_slice_for_meeting_rooms
hp elitebook_1040_g3_firmware
hp elitebook_1040_g3
hp elitebook_820_g3_firmware
hp elitebook_820_g3
hp elitebook_828_g3_firmware
hp elitebook_828_g3
hp elitebook_840_g3_firmware
hp elitebook_840_g3
hp elitebook_848_g3_firmware
hp elitebook_848_g3
hp elitebook_850_g3_firmware
hp elitebook_850_g3
hp elitebook_folio_g1_firmware
hp elitebook_folio_g1
hp elitedesk_800_35w_g2_desktop_mini_pc_firmware
hp elitedesk_800_35w_g2_desktop_mini_pc
hp elitedesk_800_65w_g2_desktop_mini_pc_firmware
hp elitedesk_800_65w_g2_desktop_mini_pc
hp mp9_g2_retail_system_firmware
hp mp9_g2_retail_system
hp probook_440_g3_firmware
hp probook_440_g3
hp probook_446_g3_firmware
hp probook_446_g3
hp probook_470_g3_firmware
hp probook_470_g3
hp probook_640_g2_firmware
hp probook_640_g2
hp probook_650_g2_firmware
hp probook_650_g2
hp rp9_g1_retail_system_firmware
hp rp9_g1_retail_system
hp z2_mini_g3_workstation_firmware
hp z2_mini_g3_workstation
hp z238_microtower_workstation_firmware
hp z238_microtower_workstation
hp z240_small_form_factor_workstation_firmware
hp z240_small_form_factor_workstation
hp z240_tower_workstation_firmware
hp z240_tower_workstation
hp zbook_15_g3_firmware
hp zbook_15_g3
hp zbook_15u_g3_firmware
hp zbook_15u_g3
hp zbook_17_g3_firmware
hp zbook_17_g3
hp zbook_studio_g3_firmware
hp zbook_studio_g3

References

Frequently Asked Questions

What is CVE-2022-37019? +
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. It has a CVSS v3.1 base score of 6.8 (MEDIUM).
How severe is CVE-2022-37019? +
CVE-2022-37019 has a CVSS v3.1 score of 6.8 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2022-37019? +
CVE-2022-37019 affects products from hp, specifically: elite_slice, elite_slice_firmware, elite_slice_for_meeting_rooms, elite_slice_for_meeting_rooms_firmware, elitebook_1040_g3, elitebook_1040_g3_firmware, elitebook_820_g3, elitebook_820_g3_firmware, elitebook_828_g3, elitebook_828_g3_firmware, elitebook_840_g3, elitebook_840_g3_firmware, elitebook_848_g3, elitebook_848_g3_firmware, elitebook_850_g3, elitebook_850_g3_firmware, elitebook_folio_g1, elitebook_folio_g1_firmware, elitedesk_800_35w_g2_desktop_mini_pc, elitedesk_800_35w_g2_desktop_mini_pc_firmware, elitedesk_800_65w_g2_desktop_mini_pc, elitedesk_800_65w_g2_desktop_mini_pc_firmware, mp9_g2_retail_system, mp9_g2_retail_system_firmware, probook_440_g3, probook_440_g3_firmware, probook_446_g3, probook_446_g3_firmware, probook_470_g3, probook_470_g3_firmware, probook_640_g2, probook_640_g2_firmware, probook_650_g2, probook_650_g2_firmware, rp9_g1_retail_system, rp9_g1_retail_system_firmware, z238_microtower_workstation, z238_microtower_workstation_firmware, z240_small_form_factor_workstation, z240_small_form_factor_workstation_firmware, z240_tower_workstation, z240_tower_workstation_firmware, z2_mini_g3_workstation, z2_mini_g3_workstation_firmware, zbook_15_g3, zbook_15_g3_firmware, zbook_15u_g3, zbook_15u_g3_firmware, zbook_17_g3, zbook_17_g3_firmware, zbook_studio_g3, zbook_studio_g3_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2022-37019? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2022-37019 — free, no signup required.